{"id":"CVE-2026-72886","summary":"Dokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of CVE-2026-45632)","details":"Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive serviceId from applicationId or composeId and execute the owner/admin host-schedule gate only in the alternative branch, allowing a member with access to one application to attach its applicationId to a dokploy-server schedule and run a supplied script as root through schedule.runManually. This issue is fixed in version 0.29.13.","aliases":["GHSA-r89g-h7x9-phr2"],"modified":"2026-08-12T04:18:53.987360370Z","published":"2026-08-10T19:38:24.177Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-269","CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72886.json"},"references":[{"type":"WEB","url":"https://github.com/Dokploy/dokploy/releases/tag/v0.29.13"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72886.json"},{"type":"ADVISORY","url":"https://github.com/Dokploy/dokploy/security/advisories/GHSA-r89g-h7x9-phr2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72886"},{"type":"FIX","url":"https://github.com/Dokploy/dokploy/commit/1e3f10bd22c1c28a7b65a2d7ac15a0a5e47599eb"},{"type":"FIX","url":"https://github.com/Dokploy/dokploy/pull/4869"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dokploy/dokploy","events":[{"introduced":"fb6b06f064b7eaa8e08878d5cfdea50ec3d774fa"},{"fixed":"1e3f10bd22c1c28a7b65a2d7ac15a0a5e47599eb"},{"fixed":"8b868c66d6672be40b86315a704ea1b3b09cb2d3"}],"database_specific":{"extracted_events":[{"introduced":"0.29.2"},{"fixed":"0.29.13"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72886.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}